Insider threat prediction based on unsupervised anomaly detection scheme for proactive forensic investigation. (October 2021)
- Record Type:
- Journal Article
- Title:
- Insider threat prediction based on unsupervised anomaly detection scheme for proactive forensic investigation. (October 2021)
- Main Title:
- Insider threat prediction based on unsupervised anomaly detection scheme for proactive forensic investigation
- Authors:
- Wei, Yichen
Chow, Kam-Pui
Yiu, Siu-Ming - Abstract:
- Abstract: The complexity, concealment and infrequency of malicious internal actions make it difficult to detect insider threats. In the process of traditional reactive forensic investigation, analysis and interpretation of the digital evidence are performed after a crime has been committed. Even if insiders can be detected, they have already caused huge damage. In this paper, we propose a novel general unsupervised anomaly detection scheme based on cascaded autoencoders (CAEs) and joint optimization network. Our core idea is to utilize CAEs to do data purification among unlabeled digital evidence, then jointly optimize the dimension reduction and density estimation network to avoid sub-optimal problems. Based on this scheme, we design an end-to-end insider threat prediction framework for proactive forensic investigation, through which we can make real time response to prevent the harmful influences of insider threats in advance. We extract the tractable and scalable feature representation automatically through the data driven Bidirectional Long Short-Term Memory (BiLSTM) feature extractor, waiving the time-consuming and customarily expert dependable feature engineering work. Additionally, a hypergraph correction module is applied to solve the commonly existed relatively high false positive rate problem in insider threat detection. We evaluate our scheme and framework on public benchmark datasets. The empirical experiments demonstrate that our models outperformAbstract: The complexity, concealment and infrequency of malicious internal actions make it difficult to detect insider threats. In the process of traditional reactive forensic investigation, analysis and interpretation of the digital evidence are performed after a crime has been committed. Even if insiders can be detected, they have already caused huge damage. In this paper, we propose a novel general unsupervised anomaly detection scheme based on cascaded autoencoders (CAEs) and joint optimization network. Our core idea is to utilize CAEs to do data purification among unlabeled digital evidence, then jointly optimize the dimension reduction and density estimation network to avoid sub-optimal problems. Based on this scheme, we design an end-to-end insider threat prediction framework for proactive forensic investigation, through which we can make real time response to prevent the harmful influences of insider threats in advance. We extract the tractable and scalable feature representation automatically through the data driven Bidirectional Long Short-Term Memory (BiLSTM) feature extractor, waiving the time-consuming and customarily expert dependable feature engineering work. Additionally, a hypergraph correction module is applied to solve the commonly existed relatively high false positive rate problem in insider threat detection. We evaluate our scheme and framework on public benchmark datasets. The empirical experiments demonstrate that our models outperform state-of-the-art unsupervised methods. … (more)
- Is Part Of:
- Forensic science international. Volume 38(2021)Supplement
- Journal:
- Forensic science international
- Issue:
- Volume 38(2021)Supplement
- Issue Display:
- Volume 38, Issue 2021 (2021)
- Year:
- 2021
- Volume:
- 38
- Issue:
- 2021
- Issue Sort Value:
- 2021-0038-2021-0000
- Page Start:
- Page End:
- Publication Date:
- 2021-10
- Subjects:
- Insider threat prediction -- Proactive forensic investigation -- Unsupervised deep learning -- Autoencoder -- Hypergraph
- Journal URLs:
- http://www.sciencedirect.com/ ↗
- DOI:
- 10.1016/j.fsidi.2021.301126 ↗
- Languages:
- English
- ISSNs:
- 2666-2817
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 20184.xml